Lucene search

K
cveMitreCVE-2006-3784
HistoryJul 24, 2006 - 12:19 p.m.

CVE-2006-3784

2006-07-2412:19:00
mitre
web.nvd.nist.gov
22
symantec
pcanywhere
12.5
weak permissions
privilege escalation
vulnerability

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

High

EPSS

0

Percentile

9.5%

Symantec pcAnywhere 12.5 uses weak default permissions for the “Symantec\pcAnywhere\Hosts” folder, which allows local users to gain privileges by inserting a superuser .cif (aka caller or CallerID) file into the folder, and then using a pcAnywhere client to login as a local administrator.

Affected configurations

Nvd
Node
symantecpcanywhereMatch12.5
VendorProductVersionCPE
symantecpcanywhere12.5cpe:2.3:a:symantec:pcanywhere:12.5:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7

Confidence

High

EPSS

0

Percentile

9.5%

Related for CVE-2006-3784